Reporting

How to schedule a report to be emailed every 15 minutes that includes all syslog events since the last report?

LokiMelkoR
Explorer

Hello

I want to generate an email report on our syslog once every 15 minutes listed down with the events on that time frame. I don't want an email for every syslog.

Sort of a Rollup email that includes whatever was seen in the last 15 minutes.

EG: if 1 Syslog in last 15 minutes 1 Email with those.
10 syslogs in last 15 minutes 1 Email with those.
20 syslogs in last 15 minutes 1 Email with those

Thank you, any help much appreciated.

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Create a search over the last 15 minutes. Save it as an alert. Schedule it to run every 15 minutes.

Set it so it sends one notification per run.

alt text

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Create a search over the last 15 minutes. Save it as an alert. Schedule it to run every 15 minutes.

Set it so it sends one notification per run.

alt text

LokiMelkoR
Explorer

Awesome, Thanks ! I tested it out. Works really good.

I would like to get this report to multiple syslogs. I only did for one (lets say host 'alpha') :
host = "alpha" 01070638

so lets say if i have bravo, charlie, echo.. etc. Do i use as,
host = "alpha" 01070638 or host = "bravo" 01070638 or host = "charlie" 01070638... etc. ?

0 Karma

jkat54
SplunkTrust
SplunkTrust

OR should be capitalized and the number / numerical string "01070638" you're searching for only needs to be entered once.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Like this

host=a OR host=b OR host=c 0123456789

LokiMelkoR
Explorer

Thanks again dude 🙂

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...